CVE-2025-71370

picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
Configurations

No configuration.

History

23 Jun 2026, 14:17

Type Values Removed Values Added
References () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-vr7h-p6mm-wpmh - () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-vr7h-p6mm-wpmh -

23 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 13:16

Updated : 2026-06-23 14:52


NVD link : CVE-2025-71370

Mitre link : CVE-2025-71370

CVE.ORG link : CVE-2025-71370


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data